Lead SOC Engineer (OT Cybersecurity)

Cpx Affiliate

Abu Dhabi

Hybride

AED 400 000 - 650 000

Plein temps

Il y a 36 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.

Passez les filtres ATS

Résumé du poste

CPX is seeking a senior OT Detection Engineer to design and implement advanced threat detection in OT environments, integrating OT telemetry into SIEM/SOAR and coordinating with SOC analysts. You will lead the development of OT-specific use cases and automate responses across OT/IT security events.

The role demands deep OT cybersecurity expertise, strong protocol knowledge (Modbus, DNP3, OPC, IEC 61850), and experience with Dragos, Claroty, Nozomi, QRadar or Splunk.

Qualifications

  • 8–10+ years in SOC operations with OT cybersecurity.
  • Lead engineering experience in an SOC/industrial cybersecurity environment.
  • Bachelor's degree in computer science, information technology, cybersecurity, or related field.

Responsabilités

  • Design, develop and tune OT-specific detection use cases and analytics in SIEM platforms.
  • Build, maintain and optimize SOAR playbooks for OT/IT security events.
  • Create, refine and document SOC alert logic for high fidelity detections.
  • Deploy, configure and optimize OT security platforms (Dragos, Claroty, Nozomi).
  • Integrate OT telemetry sources into SOC workflows (PLC logs, historian data, network telemetry, asset inventories).
  • Collaborate with SOC analysts and OT/IT teams to validate detections and improve triage processes.
  • Ensure alignment with regulatory frameworks (NESA, SAMA, NIST 800-82, IEC 62443).
  • Lead or support investigations and post-incident reviews for OT assets.

Connaissances

OT Detection Engineering
Threat Hunting
SIEM Use Cases
Telemetry Integration
Python Scripting
OT Protocols
Cross-Functional
Industrial OT

Formation

Bachelor's degree in CS/IT/Cybersecurity
Master's degree or relevant certifications

Outils

Dragos
Claroty
Nozomi
QRadar
Splunk

Description du poste

Overview

OT Detection is a senior technical and engineering leader role focused on designing and implementing advanced threat detection capabilities within OT environments. Operating within CPX's hybrid Security Operations Centers (SOCs), this role emphasizes engineering detection logic, integrating OT telemetry, and enhancing visibility across IC/SCADA systems. The position requires deep expertise in OT cybersecurity, threat hunting, and SOC operations, with a strong understanding of regional industrial sectors and compliance frameworks.

Responsibilities
  • Detection Engineering : Design, develop, and fine tune OT specific detection use cases, correlation rules, and analytics within SIEM platforms to enhance threat visibility and reduce false positives.
  • SOAR Playbook Engineering: Build, maintain, and optimize SOAR playbooks to automate investigation and response workflows for OT and IT security events.
  • Alert Development & SOC Enablement: Create, refine, and document SOC alert logic to ensure high fidelity detection and smooth operational handover to analysts.
  • Tool Integration: Deploy, configure, and optimize OT security platforms such as Dragos, Claroty, and Nozomi to improve monitoring coverage and asset visibility.

Telemetry Onboarding: Integrate OT data sources—including PLC logs, historian data, network telemetry, and asset inventories—into SIEM/SOAR and broader SOC workflows.

  • SOC Collaboration: Partner closely with SOC analysts and IT/OT teams to validate detections, enhance triage processes, and ensure seamless integration of OT monitoring capabilities.
  • Compliance Alignment: Ensure all detection and response strategies align with relevant regulatory and industry frameworks, including NESA, SAMA, NIST 800 82, and IEC 62443.
  • Incident Support: Lead or support technical investigations involving OT assets, providing deep expertise during incident response activities and post incident reviews.
Skills/Certifications (Technical & Non-Technical : -
  • Advanced OT Detection Engineering: Proven ability to design and implement high-fidelity detection logic tailored to OT environments, including IC/SCADA systems and industrial protocols.
  • Deep Protocol Expertise: Strong hands-on experience with OT/ICS protocols such as Modbus, DNP3, OPC, IEC 61850, and their behavioral patterns in threat scenarios.
  • SIEM Use Case Development: Extensive experience building and tuning OT-specific use cases and correlation rules in SIEM platforms (e.g., QRadar, Splunk), with a focus on minimizing false positives and enhancing alert fidelity.
  • Telemetry Integration: Skilled in onboarding OT telemetry sources (e.g., PLC logs, historian data, network traffic) into SOC workflows for enhanced visibility and detection.
  • Scripting & Automation: Proficient in Python and PowerShell for automating detection workflows, parsing OT logs, and building custom alerting mechanisms.
  • Cross-Domain Collaboration: Strong communication and collaboration skills to work effectively with SOC analysts, OT engineers, and incident response teams.
  • Operational Awareness: Deep understanding of SOC operations, OT threat landscapes, and the unique challenges of securing industrial environments in the Middle East.
Certifications : -
  • Cybersecurity: CISSP, CISM, or equivalent.
  • OT-Specific: GICSP, GRID, ISA/IEC 62443 Cybersecurity Certificate, Dragos, Nozomi.
  • Networking: CCNP/CCIE.
  • Additional certifications related to SOAR or SIEM solutions would be considered an advantage
Qualifications
Minimum Work Experience : -
  • Minimum of 8–10 years in SOC operations, with significant experience in OT cybersecurity.
  • Prior experience in a lead engineering role within a SOC or industrial cybersecurity environment.
Education :
  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or related field.
  • Master's degree or equivalent recognized cybersecurity certifications preferred
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Lead SOC Engineer (Devops)
Lead SOC Engineer (Devops)

CPX • Abu Dhabi

Sur place
AED 330 517 - 440 690
Senior OT Detection Engineer & SOC Automation Lead
Senior OT Detection Engineer & SOC Automation Lead

Cpx Affiliate • Abu Dhabi

Hybride
AED 400 000 - 650 000
Senior OT Threat Detection Engineer
Senior OT Threat Detection Engineer

CPX • Abu Dhabi

Sur place
AED 330 517 - 440 690
OT Security Architect
OT Security Architect

Salt • Abu Dhabi

Sur place
AED 300 000 - 400 000
OT Cybersecurity Sector Lead Analyst
OT Cybersecurity Sector Lead Analyst

Cpx Affiliate • Abu Dhabi

Sur place
AED 180 000 - 300 000
SOC Team Lead (Tier 1)
SOC Team Lead (Tier 1)

Recenso • Abu Dhabi

Sur place
AED 200 000 - 250 000
Professional development opportunities
Leadership roles
Collaborative environment
OT/ICS Cybersecurity Specialist
OT/ICS Cybersecurity Specialist

Tanqeeb • Abu Dhabi

Sur place
AED 180 000 - 240 000
SOC Specialist- L3
SOC Specialist- L3

Keka Technologies Private Limited • Abu Dhabi

Sur place
AED 446 000 - 781 000
Manager - Cyber Security - OT Security Specialist
Manager - Cyber Security - OT Security Specialist

EY Podnikatel Roku • Abu Dhabi

Sur place
AED 330 517 - 440 690
Competitive compensation package
Continuous learning opportunities
Inclusive culture
+1
OT/ICS Cybersecurity Specialist
OT/ICS Cybersecurity Specialist

VerityX • Abu Dhabi

Sur place
AED 350 000 - 750 000